monitor-sparta

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection as it processes external data (QRAs and spreadsheets) through various LLM tiers. Malicious content within the ingested data could potentially influence the validation results or the automated training loops.
  • Ingestion points: Data polled from ArangoDB and SPARTA spreadsheets as described in SKILL.md.
  • Boundary markers: No delimiters or explicit instructions to ignore embedded commands are documented for the validation process.
  • Capability inventory: The skill can execute local bash commands and trigger training via the /create-gpt skill.
  • Sanitization: No sanitization or input validation logic is present in the provided skill components.
  • [COMMAND_EXECUTION]: The skill's run.sh and sanity.sh scripts execute a Python script located at a hardcoded absolute path in the author's workspace.
  • Evidence: run.sh and sanity.sh reference and execute /home/graham/workspace/experiments/memory/scripts/validation/monitor_sparta.py.
  • Context: The path /home/graham/workspace/experiments/memory is consistent with the skill author's environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — monitor-sparta